SWI-3723 [Snyk] Security upgrade @bandwidth/messaging from 2.0.2 to 4.1.7#79
SWI-3723 [Snyk] Security upgrade @bandwidth/messaging from 2.0.2 to 4.1.7#79
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AJV-15274295 - https://snyk.io/vuln/SNYK-JS-QS-15268416
|
This is a major version upgrade that migrates the SDK to the Bandwidth Universal Platform API (v2), introducing significant breaking changes that require code modifications. Key Breaking Changes:
Recommendation: This upgrade requires a thorough review of the integration. Developers must update endpoint logic, ensure all phone numbers are passed in E.164 format, and verify authentication methods to align with the new v2 API requirements. Due to the scale of these changes, this should be handled as a significant migration effort. Source: Bandwidth API Breaking Changes
|
⛔ Snyk checks have failed. 1 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-AJV-15274295
SNYK-JS-QS-15268416
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Allocation of Resources Without Limits or Throttling